2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2756 | HIGH | 7.2 | 0.9% | May 17, 2023 | SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10. |
| CVE-2023-31208 | HIGH | 8.8 | 1.0% | May 17, 2023 | Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8... |
| CVE-2023-2745 | MEDIUM | 5.4 | 79.5% | May 17, 2023 | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. ... |
| CVE-2023-2753 | MEDIUM | 5.4 | 0.6% | May 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta. |
| CVE-2023-2752 | MEDIUM | 5.4 | 0.5% | May 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta. |
| CVE-2023-2469 | — | — | — | May 17, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-0864 | MEDIUM | 4.3 | 0.2% | May 17, 2023 | Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (... |
| CVE-2023-0863 | HIGH | 8.8 | 0.3% | May 17, 2023 | Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wal... |
| CVE-2023-2509 | MEDIUM | 6.1 | 0.3% | May 17, 2023 | A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this ... |
| CVE-2023-2706 | HIGH | 8.1 | 1.7% | May 17, 2023 | The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to th... |
| CVE-2023-2608 | MEDIUM | 4.3 | 0.4% | May 17, 2023 | The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL I... |
| CVE-2023-31847 | MEDIUM | 6.5 | 0.6% | May 17, 2023 | In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source ... |
| CVE-2023-1764 | MEDIUM | 6.5 | 0.2% | May 17, 2023 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (... |
| CVE-2023-1763 | MEDIUM | 6.5 | 0.3% | May 17, 2023 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (... |
| CVE-2023-31848 | HIGH | 8.8 | 0.6% | May 17, 2023 | davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF). |
| CVE-2023-30452 | MEDIUM | 5.4 | 0.3% | May 17, 2023 | The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map wi... |
| CVE-2023-2528 | HIGH | 8.8 | 0.3% | May 17, 2023 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in... |
| CVE-2023-25394 | HIGH | 7 | 0.3% | May 17, 2023 | Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream... |
| CVE-2023-31679 | HIGH | 7.5 | 0.8% | May 16, 2023 | Incorrect access control in Videogo v6.8.1 allows attackers to access images from other devices via modification of the ... |
| CVE-2023-31678 | MEDIUM | 5.3 | 0.6% | May 16, 2023 | Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended. |
| CVE-2023-31677 | HIGH | 7.5 | 0.8% | May 16, 2023 | Insecure permissions in luowice 3.5.18 allow attackers to view information for other alarm devices via modification of t... |
| CVE-2023-31544 | MEDIUM | 5.4 | 0.4% | May 16, 2023 | A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web... |
| CVE-2023-30281 | MEDIUM | 6.5 | 0.5% | May 16, 2023 | Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3... |
| CVE-2023-30189 | CRITICAL | 9.8 | 0.8% | May 16, 2023 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). |
| CVE-2023-29927 | MEDIUM | 4.3 | 0.4% | May 16, 2023 | Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privilege... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now